Skip to main content

Active Protection warning on trusted app.

Thread needs solution

I have cmd.exe as a trusted app in Active Protection.  When I run a batch file the Active Protection warning message still displays and prompts me to block or ignore.  I need this batch to run without user interaction.  The batch file deletes a ".tib" file.

Thanks for any help.

0 Users found this helpful

Jim, welcome to these user forums.

With active protection turned on, there are still prohibited actions, even if the app is trusted.  Deleting a .tib file is one of the prohibited actions.

I will do some tests to see if there is a work around.

Regards,

FtrPilot

 

Jim, have you tried unchecking the Active Protection setting to protect Acronis True Image files?

Clearing the check mark in Active Protection Settings to protect True Image files will allow you to delete tib files using Explorer and I suspect a batch file as well.  It also allows ransomware to modify, overwrite, delete, tib files as well.  Use at your own discretion.

There is a setting for excluding anti-ransomware monitoring for folders or files.  I excluded the folder but still received the warning message.  So it seems this setting is not working properly.

Jim, any issues with AAP should be reported to Acronis by opening a Support Case to allow them to investigate the matter more fully using the step by step details of what you are doing.

Thanks Jim, please let us know how you get on.  I have just submitted a support case for a different issue with AAP in this forum.

Jim, I tried what you did and also specified in the exclusion list to exclude the .tib files by mask. It too failed.

All this got me to thinking about how easy it should be. After all, we want a system that cannot be overridden easily. On the one hand, we are trying to exclude a folder from ransomware monitoring, but the other hand is saying to protect .tib files.

These seem to be considered two separate issues in the program. One issue is monitoring for ransomware while the other is protecting ATI files. At this point, the only way to delete the .tib is through a manual response, which is fully understandable so as not to open up the possibility of malicious software doing that.

Sounds like there should perhaps be a separate type of exclusion to handle removing .tib files.

 

 

I suspect that what we are seeing is by design (I noticed it some time back). It may be that there are two prongs to Active Protection, one is monitored folders and the other is for monitored applications - if an application is not white listed then it cannot operate on files in a folder that is not monitored. 

Well, I think that there are conflicting design elements at play.  The exclude list identifies folders and files that are excluded from anti-ransomware monitoring.  If the system prevents the deletion from the specified folder, then it is still monitoring that folder. If there are exceptions to the exclude list, i.e., ".tib" files are always monitored, the exceptions should be in the description at the top of the exclude list page.  Just a thought.

I see there was a new build released (9850) in the last 24 hours, things may have changed with that build - you never know your luck.

Ian

FYI, I worked with the first tier support.  The issue has been escalated.  I'll let you know when it has been resolved.

 

Jim

As it turns out, AP will not allow "tib" files to be deleted.  Support on this issue was great. They were very responsive.  I suggested that they add a note on the file and folder exclusion dialog that certain files and file types will not be excluded from AP protection.

Jim, thanks for passing on your feedback from your Support Case.  It makes sense that AAP will want to exclude Acronis .TIB files from being added to the file/folder exclusions list, as they are the principle focus of the protection mechanism.  I agree that there should be some more help information in this area.